SimpleSecCheck orchestrates multiple scanners inside Docker. This list is a summary; see scanner manifests for exact configuration.
- Semgrep
- CodeQL
- Trivy
- OWASP Dependency Check
- Safety
- npm audit
- Snyk (optional token)
- ESLint
- Bandit
- Brakeman
- TruffleHog
- GitLeaks
- detect-secrets
- Checkov
- Terraform Security
- Anchore (Grype)
- Clair
- Docker Bench
- Kube-bench
- Kube-hunter
- OWASP ZAP
- Nuclei
- Nikto
- Wapiti
- Burp Suite (community)
- React Native rules (Semgrep)
- Android Manifest checks
- iOS plist checks